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Amendments to the SpeciflcatiLon ; 

nease r^Iace the paragraph b^uming at page 11, line 14, which begins ^bi network 
environments using Dynamic Host Configuration Protocol" with the following amended 
paragraph: 

la' netwoji: environments using Dynamic Host Configuration Protocol (DHCP), IP 
addresses are atctomatLcally assigned to deliver TCP/IP stack configuration parametecs such as 
the subnet mask and default router, and to provide other configuration information such as the 
addresses for printer, time and news servers. In DHCP enviromnents, the ARPc ache ARP cache 
maintains lease times on assigned JP addresses of xip to four days for a direct connection. For 
dial-up connections, the DHCP lease time of the IP address is often less than an hour. Then, at 
step 306, the ARP cache of the network router that is known to have transmitted network trajQBlc 
for the missing device is searched. The device's hostname or P address will index wittiin tiie 
ARP cache to previous data packet transmissions of the n^woik device. From the data packets, 
a unique hardware fingerprint of the lost or stolen network device is extracted— such as the 
MAC address of the network adapter card contained within the missing device. If the device is 
reporting missing after a significant period time since its last access to the Jntem^,.the ARP 
cadie may have heesi flushed. In this case, the process would obtain the hardware fingerprint of 
the missing device throu^ an alternative method. For example, previous emails sent from the 
missing device or other artifacts sent over the network can be extracted ftom other receivjng 
netwoik machines, and then the device's MAC address or other hardware fingeaprint can he 
^tracted therefrom. 
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Please replace the paragraph beginnmg at page 13, line 1, which begins ^Once the network 
server is alerted" wilh the following amended paragraph: 

Once the network server is alerted that the missing machine has been used on the 
network, the rest of the network enveloping information in the missing madiine's Internet trafBLc 
is used to attempt to isolate the computer's location. The intercepted data packets are decompiled 
and are used to trace the route through which the data has traveled and to extract the IP address 
jGrom which they originated. In accordance with the preferred embodiment, when a match is 
discovered in the hxtemet traffic for the hardware fingerprint of a device Usted in the missing 
equipment database, a tracing software routine is initiated in a network server that determiaes the 
Internet communication links that were used to connect the missing netwoik device to tibie 
network server. These Internet communication links will assist the network server in tracking 
the netwoik device and obtaining its IP address. The IP address of the source^ of « a DNS 
query is sent to the host within the DNS query that starts the intercepted netvirork traffic. 
However, if the source of the qoery is transmitted through a "proxy" server, thenihe IP address 
of the client compute (which may not be unique since it may not have been assigned by the 
InterNIC) will likely be io$uj6ficient to track the location of the cUent computer. In such a 
sc^iaiio, it is necessary to determine the addresses of ottier IP touters whioh were accessed to 
liable commumcatLon between the client and the host These addresses and the times that tihey 
were accessed are compared with internal logs of the proxy server which record its clients* 
Int^et access history. In this way, the cliesnt can be uniquely identified and located. 



Page 3 of 13 



PA(£4n4'R(M)AT7/15/20054:31:37PM [Eastern Daylight 



